Signature certificate
A signature certificate is a PDF that documents, in a court‑ready form, who signed a document, when, how their identity was verified and that the content was not changed. It is built from the tamper‑evident audit log (ImmuDB) and sealed with 16IT's qualified electronic seal, so its own integrity can be verified independently.
The certificate is free and is sent to your e‑mail — it is not the signed document itself, but an evidence sheet describing the signatures on it.
How to order
You can order a certificate only for a fully signed document (every signer has signed).
-
Open the signed document. In the right panel, next to Download document, open the ⌄ menu and choose Order signature certificate.
-
A dialog explains what the certificate is and that it will arrive by e‑mail within 24 hours. Click Confirm.
-
A confirmation appears — the order has been accepted. The certificate is generated asynchronously and e‑mailed to the address of the account that ordered it.
Ordering again while a certificate is still being generated is rejected. If a certificate was already generated, ordering again simply re‑sends it by e‑mail.
How to read it
Each signature on the document gets its own Signature N section. The fields fall into two groups: common fields shown for every signature, and method‑specific fields that depend on how the signer confirmed their identity (SES / AES via SMS, National Node or passkey / QES).
Common fields (every signature)
| Field | Meaning |
|---|---|
| Signing date and time | When the signature was made, in the reader's time zone. |
| Signer | Signer's name (for QES, taken from the qualified certificate). |
| E‑mail | Signer's e‑mail (for QES, from the certificate when no signer record). |
| Signature type | SES or QES. |
| Verification | Plain‑language description of how identity was verified. |
| IP address | IP address the signature was made from. |
| User agent | Browser / device used. |
| Document hash before signing (SHA‑256) | Hash of the document as this signer received it. |
| Document hash after signing (SHA‑256) | Hash of the document after this signer's seal was added. |
Signatures are added on top of the document (append‑only), so the file's hash changes with each signature — this is expected, not tampering. For a chain of signers, one signer's after hash equals the next signer's before hash, which shows the order and that nobody signed a substituted document.
SES — simple signature
No extra fields. Only the common fields above. Verification reads as confirmed by e‑mail.
Identity verification — via SMS
Common fields plus:
| Field | Meaning |
|---|---|
| Phone number | The number the one‑time SMS code was sent to. |
Identity verification — via National Node (Węzeł Krajowy)
Common fields plus the identity attributes returned by the national identity node:
| Field | Meaning |
|---|---|
| Verification system | The node used (e.g. Polish National Node). |
| Person identifier | National identifier of the signer. |
| First name / Family name | Names confirmed by the node. |
| Date of birth / Birth name / Place of birth / Gender / Current address | Identity attributes from the national profile. |
Identity verification — via passkey (WebAuthn)
The strongest verification method: the signer confirms with a device passkey (fingerprint, face or PIN). Besides the common fields, the certificate records the full cryptographic proof. Most of these are technical / forensic fields aimed at auditors:
| Field | Meaning |
|---|---|
| Phone number | Signer's number (identity was also SMS‑verified). |
| Identity verification method | How identity was verified before the passkey was registered (SMS). |
| WebAuthn confirmation time | When the passkey confirmation happened. |
| WebAuthn challenge | The exact data the passkey signed — a random nonce plus the document hash. |
| Nonce | One‑time random value inside the challenge (prevents replay). |
| Relying party ID / Request origin | The domain and origin the signature is bound to. |
| Request ID / Credential ID | The signing‑request ID and the passkey's identifier. |
| WebAuthn init type | create (first signature on this device, registers the passkey) or get (later signatures). |
| Authenticator AAGUID | Identifier of the authenticator model. |
| Authenticator transports | How the authenticator is reached (internal, hybrid, usb, nfc, ble). |
| Backup eligible | Whether the passkey is syncable (e.g. iCloud / Google). Platform passkeys are usually true. |
| User verification (UV) | true means the user was verified on the device (biometrics or PIN). |
| Attestation type | Usually none for platform passkeys — proof of possession comes from the assertion, not attestation. |
| Signature counter (before) / counter | Authenticator sign counter. Synced passkeys report 0 and do not change — this is normal. |
| COSE public key hash (SHA‑256) | Hash of the passkey's public key. |
| Client Data Json Sha256 | Hash of the signed client data. |
| Attestation object hash (SHA‑256) | Hash of the registration attestation. |
| Authenticator data hash (SHA‑256) | Hash of the authenticator data covered by the signature. |
| Assertion signature hash (SHA‑256) | Hash of the passkey signature over the challenge. |
Raw binary values (public key, client data, attestation, authenticator data, signature) are not printed — only their SHA‑256 hashes, which are enough to verify the evidence without exposing bulky data.
QES — qualified signature
Common fields plus details extracted from the signer's qualified certificate and the validation of their signature:
| Field group | Fields | Meaning |
|---|---|---|
| Signature | Signature format, Signature algorithm, Digest algorithm, Claimed signing time, Signature qualification, Signature integrity, PDF sub‑filter, Signature field name, Signature count, Reason, Location, Signature ID | Technical properties of the PAdES signature and the validation result (e.g. qualification QESig, integrity true). |
| Certificate | Subject serial number, Certificate serial number, Organization, Country, Subject DN, Issuer DN, Valid from / Valid to | Details of the qualified certificate and its issuing CA. |
| Uploaded file | Uploaded file name, size, content type | The QES‑signed file the signer uploaded. |
For QES the Signer and E‑mail common fields come from the qualified certificate (subject common name and certificate e‑mail).
trace_id / correlation_id are stored internally for support but are not printed on the
certificate.
For how each signature type is made, see Simple (SES), Electronic signature with identity verification and Qualified (QES). To verify a certificate or a signed PDF yourself, see Online verification and Validate a PDF manually.